Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fwr-mh5q-hchh

Опубликовано: 26 фев. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout

A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are made. If a client request times out, a buffer is not released correctly, leading to increased memory usage and eventual application crash due to OutOfMemoryError.

Пакеты

Наименование

io.quarkus:quarkus-resteasy

maven
Затронутые версииВерсия исправления

>= 3.16.0.CR1, < 3.19.1

3.19.1

Наименование

io.quarkus:quarkus-resteasy

maven
Затронутые версииВерсия исправления

>= 3.9.0.CR1, < 3.15.3.1

3.15.3.1

Наименование

io.quarkus:quarkus-resteasy

maven
Затронутые версииВерсия исправления

< 3.8.6.1

3.8.6.1

EPSS

Процентиль: 67%
0.00555
Низкий

7.5 High

CVSS3

Дефекты

CWE-401

Связанные уязвимости

CVSS3: 7.5
redhat
10 месяцев назад

A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are made. If a client request times out, a buffer is not released correctly, leading to increased memory usage and eventual application crash due to OutOfMemoryError.

CVSS3: 7.5
nvd
10 месяцев назад

A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are made. If a client request times out, a buffer is not released correctly, leading to increased memory usage and eventual application crash due to OutOfMemoryError.

EPSS

Процентиль: 67%
0.00555
Низкий

7.5 High

CVSS3

Дефекты

CWE-401